SonicWall has revealed another critical security flaw in its internet-facing appliance, the third maximum-severity vulnerability in the same product line in roughly three months. CVE-2026-102255, which scores 10 on the Common Vulnerability Scoring System, affects the SMA1000 Appliance Work Place interface and allows pre-authentication server-side request forgery (SSRF) attacks. The cybersecurity firm also disclosed three additional vulnerabilities of lower severity impacting the same appliance and strongly recommends that customers upgrade immediately to the patched software version.

The newly disclosed flaw impacts SMA 1000 Models 6210, 7210, and 8200v running software versions 12.4.3-03526 and 12.5.0-02952 and earlier. An unintended access path could enable attackers to force the appliance to issue requests on their behalf and gain access to internal functions to perform unauthorized actions. The three other vulnerabilities include CVE-2026-102256, rated 7.8, which could let a remote authenticated attacker take over as admin and execute arbitrary OS commands; CVE-2026-102257, rated 7.2, that could enable path traversal and remote code execution; and CVE-2026-102258, rated 5.5, which under specific conditions could give a remote authenticated attacker the ability to store and potentially execute arbitrary JavaScript code in the appliance management console. SonicWall credited researchers from Anthropic, Trend Micro, and DigitalCanion SA for discovering the flaws. The company said there's no evidence yet that the critical vulnerability is being exploited in the wild, though the vulnerabilities don't impact SSL-VPN running on SonicWall firewalls or the SMA 100 Series product line.

Frank Dickson, principal analyst at Dickson Research, noted that CVSS only awards a 10.0 "when everything goes the attacker's way." According to Dickson, this flaw can be accessed over the network, an attack is easy to pull off and needs no credentials or for a user to click anything to succeed. David Shipley, CEO of Beauceron Security, agreed, explaining that CVE-2026-102255 is rated 10 in severity because it allows an attacker to completely hijack a security device remotely before any authentication comes into play. The report notes that the fixed releases are now 12.4.3-03670 and 12.5.0-03082 or later, and the advisory lists no workaround for the bug other than patching.

The SMA 1000 sits on the network edge for the precise reason that it can reach what's behind it, and SSRF attacks borrow that trust by asking the appliance to knock on internal doors that open because the request seems to come from someone the system trusts. Dickson pointed out that software versions 12.4.3-03526 and 12.5.0-02952 listed as affected are the very hotfixes that fixed September's zero-days, meaning a customer who did everything right last month is exposed again today. The SMA appliances have been riddled with vulnerabilities of late, actively exploited by attackers: in September, the company reported two major security holes in the 1000 series, and in July, a pre-authentication forgery flaw was exploited as a zero-day vulnerability. Over the last four years, the US Cybersecurity and Infrastructure Security Agency has added 19 SonicWall vulnerabilities to its list of actively exploited flaws, with thirteen of these targeted in ransomware attacks.

Dickson's advice includes verifying the full build on every appliance, taking the workplace interface and management console off the open internet where possible, and treating this patch as the start of an investigation if an appliance sat exposed and unpatched during the July or September windows. SonicWall's guidance after previous incidents was to re-image, rotate passwords, and reset time-based one-time passwords, and this advice still stands. Shipley warned that because two of the highest-severity vulnerabilities were discovered by Anthropic researchers, a whole host of AIs will replicate this attack now that it's public, and he advised checking logs and hunting for this entire bug class deep within products. Dickson noted that three 10.0 flaws in one interface in about three months is a pattern, not bad luck, and customers should ask SonicWall whether the current vulnerabilities are new bugs or just incomplete fixes for previous issues. Enterprises relying on perimeter appliances face a structural dilemma that vendor rotation alone won't resolve, as every major remote access platform eventually becomes a favored intrusion vector. Security teams must decide whether to accept iterative patching cycles or fundamentally rethink edge architecture before the next critical disclosure arrives.